OT Detection Engineer in Manchester

OT Detection Engineer in Manchester

Manchester Full-Time 45000 - 55000 £ / year (est.) Home office (partial)
NCC Group plc

At a Glance

  • Tasks: Join our team to develop cutting-edge detection logic for OT environments.
  • Company: Global leader in Cyber Services with a focus on innovation.
  • Benefits: Flexible working, generous holiday allowance, and community volunteering opportunities.
  • Other info: Opportunities for career growth and learning in a supportive team.
  • Why this job: Make a real impact in cybersecurity while growing your skills in a dynamic environment.
  • Qualifications: Experience in IT systems or network administration; passion for security is key.

The predicted salary is between 45000 - 55000 £ per year.

Our Global Detection Engineering Team provides detection capabilities for various security products used in our 24/7 managed monitoring service with customers all over the world. This role will be to join our detection engineering team, where you will focus on developing the best detections for OT environments utilizing our Network Sensor, supporting our NDR for OT service. You will use our latest Threat Intelligence and your own creativity to write and maintain detection logic for our customers. Previous experience with detection engineering is not a prerequisite. We are looking for a wide range of backgrounds for potential candidates, and the exact responsibilities of any candidate can be tailored given their experience and skill set. Any candidate that only partially matches the skill set is encouraged to apply.

The Opportunity

  • Develop, validate, tune and optimise network sensor detection logic specific to OT environments.
  • Integrate network telemetry into SIEM and SOAR platforms.
  • Support client‑facing teams in network sensor deployments and configuration baselines.
  • Write and maintain detection test cases.
  • Review findings of TI, CERT, and Red Team activities and evaluate from a detection engineering improvement perspective.

Key Responsibilities

  • Research data sets and potential IOCs for distribution.
  • Run tools/techniques to acquire data.
  • Research log sources and data sets.
  • Write rules and alert logic.
  • Write test processes and procedures for the logic.
  • Monitor test output and fix bugs.
  • Monitor the system & data health.
  • Add global filters to detection logic based on operational feedback.
  • Deploy new analytics to existing customers using our deployment pipeline(s).
  • Ensure work is up‑to‑date or tracked.

Skills, Knowledge & Expertise Minimum Requirements:

  • Proven experience with and understanding of industrial environments and protocols (such as Modbus, S7Comm, S7Comm+, Bacnet, Profinet, DNP3, OPC, MQTT).
  • Proven experience and general understanding of detection engineering, tuning and optimisation of detection logic with Suricata, Zeek or vendor platforms (such as Dragos, Nozomi, Claroty, Armis or Darktrace).
  • Proven experience in SOC or Managed Detection Services.
  • Alternative Path: Proven experience in analytically‑minded IT Systems administration/Network Administration looking for a career change/focus on Security.
  • Excellent oral and written communication skills in English.
  • Ability to work with client engagement teams and NCC colleagues to continuously improve the service we deliver.
  • Good understanding of IT Systems and platforms from a security context.
  • A security mindset and demonstrable experience or knowledge of contemporary attack tactics and techniques specific for OT environments.
  • Forensics or Incident Response competency would be considered valuable.
  • Strong knowledge of the latest threats in security or an eagerness to build this knowledge.
  • Experience with simulating attacks.
  • Certificates such as CEH and OSCP are not required but are a plus.
  • Experience with network detection tools, preferably Zeek, Suricata, Nozomi, Claroty, Armis or Dragos.
  • Experience with scripting languages such as PowerShell, Python, Bash.
  • Experience with version control (Git, Azure Dev Ops, etc.).
  • And has knowledge of one or more of the below:
    • Networking fundamentals.
    • ICS/SCADA.

Job Benefits

  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco‑friendly car scheme.
  • Cycle Scheme: Stay fit and healthy with our cycle‑to‑work scheme.
  • Special Time Off: Take time off for those big moments in life, such as getting married, entering a civil partnership, becoming a grandparent and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.

OT Detection Engineer in Manchester employer: NCC Group plc

Join our dynamic Global Detection Engineering Team in Manchester, where we foster a collaborative and innovative work culture that prioritises employee growth and development. With flexible working options, generous holiday allowances, and a commitment to community engagement, we offer a rewarding environment for those passionate about cybersecurity in operational technology. Our unique benefits, including a Green Car Scheme and special time off for life events, make us an exceptional employer for individuals seeking meaningful and impactful careers.

NCC Group plc

Contact Details:

NCC Group plc Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land OT Detection Engineer in Manchester

Tip Number 1

Network, network, network! Reach out to folks in the industry, especially those already working in OT detection or cybersecurity. Use platforms like LinkedIn to connect and engage with professionals; you never know who might have a lead on your dream job!

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing any relevant projects or scripts you've worked on. This is a great way to demonstrate your capabilities and creativity in detection engineering, especially if you're transitioning from another field.

Tip Number 3

Prepare for interviews by brushing up on common questions related to OT environments and detection logic. Practice explaining your thought process when tackling detection challenges, as this will show your analytical mindset and problem-solving skills.

Tip Number 4

Don’t hesitate to apply through our website! Even if you don’t meet every single requirement, we value diverse backgrounds and experiences. Your unique perspective could be just what we need in our detection engineering team!

We think you need these skills to ace OT Detection Engineer in Manchester

Detection Engineering
Network Sensor Configuration
Threat Intelligence Analysis
Data Acquisition Techniques
Log Source Research
Rule Writing and Alert Logic
Test Process Development

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your relevant skills and experiences. We want to see how your background aligns with the OT Detection Engineer role, so don’t hold back on showcasing your unique strengths!

Show Off Your Passion:Let us know why you’re excited about this position! Whether it’s your interest in detection engineering or your enthusiasm for OT environments, sharing your passion can really make your application stand out.

Be Clear and Concise:When writing your application, keep it straightforward and to the point. We appreciate clarity, so avoid jargon and ensure your key points shine through. This helps us understand your qualifications quickly!

Apply Through Our Website:We encourage you to submit your application directly through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy!

How to prepare for a job interview at NCC Group plc

Know Your OT Protocols

Make sure you brush up on your knowledge of industrial protocols like Modbus, S7Comm, and DNP3. Being able to discuss these confidently will show that you understand the environment you'll be working in.

Showcase Your Detection Engineering Skills

Even if you don't have direct experience, highlight any relevant skills or projects related to detection logic, tuning, or optimisation. If you've worked with tools like Suricata or Zeek, be ready to discuss your experiences and how they relate to the role.

Prepare for Client Engagement Scenarios

Since this role involves working with client-facing teams, think of examples where you've successfully communicated technical information to non-technical stakeholders. This will demonstrate your ability to bridge the gap between technical and client needs.

Stay Updated on Security Trends

Familiarise yourself with the latest threats and attack tactics specific to OT environments. Showing that you're proactive about staying informed will impress interviewers and highlight your security mindset.